<div dir="ltr">I'll copy it into my JETTY_BASE and restore the original file in JETTY_HOME. I'm new to Jetty, came from the Tomcat world and wasn't even using a separate JETTY_BASE until recently.</div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div>~Matt</div></div></div></div></div></div>
<br><div class="gmail_quote">On Wed, Mar 22, 2017 at 11:05 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> In jetty.xml in my JETTY_HOME/etc/ (might work in JETTY_BASE but didn't try) I added the below code in the httpConfig block:<br>
<br>
</span>You never change any file in jetty-home.<br>
<span class=""><br>
> In HAProxy, which I am using as my load balancer, I added "http-request del-header X-Forwarded-For" to the frontend block, so<br>
> someone on the outside cannot spoof that header. Also make sure to put "option forwardfor" in your backend, so you get the<br>
> X-Forwarded-For header passed on.<br>
<br>
</span>I think there would be a lot of interest in how you configured HAProxy in the wiki in a HowTo.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>